Metrics
Affected Vendors & Products
Wed, 04 Jun 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Assimp
Assimp assimp |
|
CPEs | cpe:2.3:a:assimp:assimp:5.4.3:*:*:*:*:*:*:* | |
Vendors & Products |
Assimp
Assimp assimp |
Wed, 28 May 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 27 May 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Mon, 26 May 2025 03:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file assimp/code/AssetLib/MDC/MDCLoader.cpp of the component MDC File Parser. The manipulation of the argument pcVerts leads to out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. | |
Title | Open Asset Import Library Assimp MDC File Parser MDCLoader.cpp InternReadFile out-of-bounds | |
Weaknesses | CWE-119 CWE-125 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-05-26T03:00:12.418Z
Updated: 2025-05-28T17:37:05.775Z
Reserved: 2025-05-25T13:14:23.794Z
Link: CVE-2025-5166

Updated: 2025-05-27T14:19:57.703Z

Status : Analyzed
Published: 2025-05-26T04:15:28.370
Modified: 2025-06-03T15:40:15.497
Link: CVE-2025-5166
